Hgiga MailSherlock是中国恒基(Hgiga)公司的一套企业邮件审核系统。 HGiga MailSherlock 存在跨站脚本漏洞,该漏洞源于没有正确验证特定的URL参数,这使得攻击者可利用该漏洞可以为XSS攻击注入JavaScript语法。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HGiga | MailSherlock MSR45/SSR45 | unspecified ~ 120 | - |
|
| HGiga | MailSherlock MSR45/SSR45 | unspecified ~ 133 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-25848 | 9.8 CRITICAL | HGiga MailSherlock - Broken Authentication |
| CVE-2020-25850 | 8.1 HIGH | HGiga MailSherlock - Arbitrary File Download |
| CVE-2020-35851 | 8.1 HIGH | HGiga MailSherlock - Command Injection |
| CVE-2020-35741 | 7.0 HIGH | HGiga MailSherlock - XSS -2 |
| CVE-2020-35742 | 7.0 HIGH | HGiga MailSherlock - SQL Injection -1 |
| CVE-2020-35743 | 7.0 HIGH | HGiga MailSherlock - SQL Injection -3 |
No comments yet